35,000+ World Cup Fake Sites Trap Fans

Trend Micro Simply Security · Medium sophistication
Last updated July 30, 2026

Researchers tracked a large scam wave abusing interest in the 2026 FIFA World Cup, including fake merchandise stores, cloned ticket sites, and bogus “free streaming” pages. The most harmful scams used near-perfect ticket-site clones to steal login details, credit card data, and one-time passwords in real time to push through fraudulent payments. Users were commonly pulled in via search results manipulated by SEO poisoning, then redirected through multiple pages to scam destinations.

How the Scam Wave Operated

Researchers tracked more than 35,000 malicious or suspicious World Cup related sites between January and June 2026, with a large share of visits coming from Japan. The scam wave spanned three main categories: counterfeit merchandise shops, cloned ticket and hospitality sites, and fake live-streaming pages. Each category relied on a slightly different lure, but all of them depended on getting a fan to click a link outside the official channel.

The most damaging variant was the cloned ticket site. These pages nearly perfectly replicated an official FIFA hospitality and ticket purchase experience. Victims entered an email and password, which went straight to the attackers, then supplied credit card details. At the final step, the fake site prompted the user to enter a one-time password on its own payment screen. That let attackers use the OTP in real time to push through a fraudulent charge, defeating protections like 3-D Secure that are designed to stop exactly this kind of fraud.

Why the Attack Succeeded

A major factor was SEO poisoning. Searches for phrases like free World Cup streaming or FIFA merchandise were manipulated so scam pages ranked highly in search results. Clicking through often carried the victim across a chain of relay pages hosted on blogging platforms before landing on the final fake site, making the path harder to trace back to a single source. The scarcity and excitement around a major event like the World Cup also pushed people to move quickly rather than verify the site first.

What to Watch For

  • Being asked to enter a one-time password directly inside a merchant checkout page rather than through a bank or card issuer's own verification flow
  • Streaming pages that flash a message saying registration is required to watch, then ask for personal or payment details
  • Shopping or ticket sites reached only through a search result or ad link, rather than a direct navigation to the known official URL
  • Video players that never actually play and instead trigger repeated redirects

Building Resistance

The clearest defense is navigating directly to official ticket, merchandise, and streaming sites rather than clicking search or social ad links. Treat words like free and official with skepticism, especially around streaming offers. Before entering any one-time password, confirm the merchant and amount match the intended purchase, and stop immediately if anything looks off. Using a unique password for every service also limits the damage if credentials are captured by a lookalike site, since a single stolen password should not be able to unlock other accounts.

Key findings

  • TrendAI tracked 35,538 malicious/suspicious World Cup-related sites from Jan–Jun 2026, with ~1.48 million visits from Japan.
  • Scam types included counterfeit merchandise shops, cloned ticket/hospitality sites, and fake live-streaming pages.
  • Cloned ticket sites harvested credit card details and one-time passwords (OTP) in real time to complete fraudulent payments even with MFA/3-D Secure.
  • Fake streaming scams used SEO poisoning and redirections via relay pages and ad networks; some prompted users that “registration is required to watch” to harvest data or enroll victims into subscriptions.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance (card/payment awareness), Travel/Events coordinators, Anyone who purchases tickets online.
  • Affected industries: Sports & entertainment (event ticketing and hospitality), Retail / e-commerce (merchandise shops), Media and streaming services, Financial services (card payments/3-D Secure flows), Education / research (compromised university research institute website).
  • Attack channels: website.
  • Impersonated: Official FIFA hospitality/ticket site, Japanese broadcasters and streaming services (posed as), Legitimate Japanese online stores (lookalike shops).

Red flags to watch for

  • Site is a clone that is not connected to the real FIFA account system
  • OTP is requested inside the merchant page instead of a trusted bank/card verification flow
  • Too-good-to-be-true availability/pricing and high-pressure checkout experience
  • Uses “free streaming” bait and asks for registration/credit card details
  • Multiple redirects (compromised site → relay pages → final fake streaming site)
  • Video never actually plays; repeated clicks trigger redirects to unrelated sites
  • Found via manipulated search rankings (SEO poisoning)
  • Store looks legitimate but items “often never arrive” or are counterfeit
  • Domain/URL and branding inconsistencies compared to official retailers
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the fake FIFA ticket sites steal money despite MFA?

The cloned sites harvested credit card details and then prompted victims to enter the one-time password directly on the fake payment screen, letting attackers use it in real time to complete fraudulent charges even when 3-D Secure was in place.

How were victims led to these fake World Cup sites?

Many users found the scam sites through manipulated search results, a technique known as SEO poisoning, and were then redirected through relay pages hosted on blogging platforms before landing on the fake destination.

What are the warning signs of a fake ticket or streaming site?

Red flags include being asked to enter an OTP on a merchant page instead of a bank verification flow, prompts claiming registration is required to watch a stream, and too-good-to-be-true pricing or availability.

What should someone do if a site asks for an OTP during checkout?

They should verify that the merchant and amount match their actual purchase, and if anything looks off, stop without entering the code and contact their card company or bank directly.

Read the video transcript

In 2026, over thirty‑five thousand fake World Cup sites popped up, some look exactly like the real FIFA ticket page. You land on a site that almost completely replicates the official FIFA hospitality page. It asks you to log in, enter your card, then type the one‑time password on its own payment screen, while it pushes through a real charge in the background. Same play with streaming: you search 'fifa ワールドカップ 2026 無料配信', click a top result, bounce through a few pages, land on a fake broadcaster with a video that never plays, only 'registration required to watch' and a credit card form. Here’s the move: for World Cup tickets, merch, or streams, never trust search results or ads, type the official site address yourself and only enter an OTP in your bank’s own verification screen.

Similar attacks

Fake FIFA Ticket Sites Steal Cards and OTPs

Fake FIFA Ticket Sites Steal Cards and OTPs

Researchers and the FBI warn that criminals are luring World Cup fans to convincing fake FIFA ticket websites, often via social media ads and shared links. The…

July 16, 2026